audit-skills

Audit AI Skills and Bundles for security vulnerabilities via static analysis.

Updated Mar 21, 2026
One-click install
npx skills add https://github.com/d0whc3r/hackaton-cubepath --skill audit-skills-d0whc3r
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: audit-skills
Source: https://github.com/d0whc3r/hackaton-cubepath/tree/main/.agents/skills/audit-skills
Command: npx skills add https://github.com/d0whc3r/hackaton-cubepath --skill audit-skills-d0whc3r

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Expert security auditing for AI Skills and Bundles. Performs non-intrusive static analysis to identify malicious patterns, data leaks, system stability risks, and obfuscated payloads across Windows, macOS, Linux/Unix, and Mobile (Android/iOS).

Core Features & Use Cases

  • Non-intrusive static analysis to detect malicious patterns, data leaks, stability risks, and obfuscated payloads across Windows, macOS, Linux/Unix, and Mobile (Android/iOS).
  • Platform-specific threat detection for cross-platform security assessment.
  • Use cases: security reviews, risk assessment of AI skills, compliance verification.

Quick Start

Run a static security audit on the target skill bundle and report any vulnerabilities.

Frequently Asked Questions about audit-skills

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a security audit on AI skills to detect data leakage?

To perform a security audit on AI skills, run a non-intrusive static analysis to detect data leakage, malicious patterns, and obfuscated payloads without executing the skill code.

What is non-intrusive static analysis for cross-platform threat detection?

Non-intrusive static analysis for cross-platform threat detection identifies vulnerabilities like privilege escalation and data leaks across Windows, macOS, Linux, and mobile platforms without running the code.

Can I use static analysis to find obfuscated payloads in AI skill bundles?

Yes, you can use static analysis to find obfuscated payloads in AI skill bundles by scanning for malicious patterns and stability risks while assessing cross-platform compliance.

Does cross-platform security assessment work for mobile Android and iOS AI skills?

Cross-platform security assessment works for mobile Android and iOS AI skills by applying platform-specific threat detection to identify vulnerabilities, data leaks, and stability issues.

What is the best way to check compliance and mitigate risks in AI bundles?

The best way to check compliance and mitigate risks in AI bundles is through expert security auditing that provides risk-mitigation guidance based on static analysis of malicious patterns.

Why does static analysis fail to detect dynamic privilege escalation in AI skills?

Static analysis focuses on non-intrusive code inspection to identify vulnerabilities, meaning it may not detect dynamic privilege escalation occurring only during runtime execution of AI skills.